Only show wallet details screen when appropriate
What changed, and why it matters
This commit changes two wallet setup screens so that users running a 'full node' mode skip a 'wallet details' screen that is only relevant to users relying on a third-party light wallet service. It also moves the start of a fiat-rate service earlier in the flow. There is no direct security vulnerability in the diff; it is a UI/routing correction that may reduce user confusion and avoid exposing unnecessary setup steps.
No security action required. Reviewers may want to verify that /lws_details does not perform any side effects when bypassed, and that full-node users still receive all required setup information.
Security signals we found
UI flow change that reduces exposure of LWS whitelisting configuration to full-node users
No cryptographic, authentication, or authorization changes
No input validation or output encoding changes
No network or storage changes
Evidence from the diff
In generate_seed.dart and restore_wallet.dart, the post-setup navigation now checks appWalletOf(context).isNodeMode. If true, it pushes directly to /wallet_home; otherwise it pushes to /lws_details with the restore height. The FiatRateModel.startService() call is moved before navigation in generate_seed.dart and already precedes navigation in restore_wallet.dart. The comment explicitly states ‘/lws_details’ contains LWS (likely ‘Light Wallet Server’) whitelisting info that full-node users do not need.
Changed components
lib/screens/generate_seed.dartlib/screens/restore_wallet.dartInspect captured patch +17 / −2
diff --git a/lib/screens/generate_seed.dart b/lib/screens/generate_seed.dart
index 7114ac3..b69e82e 100644
--- a/lib/screens/generate_seed.dart
+++ b/lib/screens/generate_seed.dart
@@ -54,13 +54,18 @@ class _GenerateSeedScreenState extends State<GenerateSeedScreen> with SecureScre
}
void _continue() {
+ Provider.of<FiatRateModel>(context, listen: false).startService();
+ // Wallet Details is LWS whitelisting info; a full node needs none of it.
+ if (appWalletOf(context).isNodeMode) {
+ Navigator.pushNamedAndRemoveUntil(context, '/wallet_home', (Route<dynamic> route) => false);
+ return;
+ }
Navigator.pushNamedAndRemoveUntil(
context,
'/lws_details',
(Route<dynamic> route) => false,
arguments: _restoreHeight,
);
- Provider.of<FiatRateModel>(context, listen: false).startService();
}
@override
diff --git a/lib/screens/restore_wallet.dart b/lib/screens/restore_wallet.dart
index d6de064..195adfb 100644
--- a/lib/screens/restore_wallet.dart
+++ b/lib/screens/restore_wallet.dart
@@ -130,7 +130,17 @@ class _RestoreWalletScreenState extends State<RestoreWalletScreen> with SecureSc
if (mounted) {
Provider.of<FiatRateModel>(context, listen: false).startService();
- Navigator.pushNamedAndRemoveUntil(context, '/wallet_home', (Route<dynamic> route) => false);
+ // Wallet Details is LWS whitelisting info; a full node needs none of it.
+ if (appWalletOf(context).isNodeMode) {
+ Navigator.pushNamedAndRemoveUntil(context, '/wallet_home', (Route<dynamic> route) => false);
+ } else {
+ Navigator.pushNamedAndRemoveUntil(
+ context,
+ '/lws_details',
+ (Route<dynamic> route) => false,
+ arguments: restoreHeight,
+ );
+ }
}
}
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.